Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
ledger-live[.]stratorient[.]com
“Ledger”
On July 25, 2026, the domain ledger-live.stratorient.com was identified as an active crypto‑scam impersonating the Ledger brand. The site returns HTTP 200 and presents a page title of “Ledger”, indicating an attempt to appear legitimate to credential‑seeking victims. Registration data shows the domain was created on February 21, 2026 and is registered through GMO Internet Group, Inc. d/b/a Onamae.com. Hosting is provided by Psychz Networks (AS40676) in the United States, resolving to IP address 104.234.134.14.
The TLS certificate is issued by Let’s Encrypt (R13), which is typical for low‑cost or abuse‑oriented infrastructure. Reputation checks reveal a Gridinsoft trust score of 0 / 100 and the domain appears on one security blocklist, with PhishDestroy already listing it as blocked. VirusTotal analysis flags the domain in 12 of 93 scanned security vendors, reinforcing the malicious classification. Detected front‑end technologies include Bootstrap, jQuery and HTTP/3, which are commonly used in phishing kits but do not independently confirm malicious intent.
Nameservers ns1.hostseba.com and ns2.hostseba.com are associated with the hosting provider and have been observed in other abuse reports. While the page content has not been examined directly, the combination of brand impersonation, low trust score, blocklist inclusion, and multiple vendor detections provides strong evidence of a credential‑harvesting operation targeting Ledger users. Defenders should add ledger-live.stratorient.com to URL filtering and DNS blocklists, monitor traffic to the associated IP 104.234.134.14, and consider extending detection rules to include the observed nameserver pattern. Continuous re‑evaluation is advised in case additional subdomains or infrastructure are leveraged in the campaign.
Gönderilen rapor kaydı
Gönderilen kanıt anlık görüntüsü
- Gönderildi
- Kayıt defteri kayıtları
- 1
- Vaka kimliği
PD-20260211-BF5105- PDF belgesi
- PDF kanıtı
Kanıtın tam metni
Acceptable Use Policy: The domain ledger-live.stratorient.com is engaged in phishing activities, which directly contravenes your AUP by facilitating fraud and deception.
Terms of Service: The use of this domain for illegal activities constitutes a violation of your TOS, which reserves the right to suspend or terminate services for such infractions.
Applicable Laws (JP):
Act on Prohibition of Unauthorized Computer Access (Act No. 128 of 1999): This law prohibits unauthorized access to computer systems, which is applicable in cases of phishing.
Act on Regulation of Transmission of Specified Electronic Mail (Act No. 26 of 2002): This law addresses the illegal transmission of deceptive electronic communications, including phishing schemes.
Penal Code of Japan (Act No. 45 of 1907): Articles related to fraud and forgery are relevant, as phishing is a form of fraudulent activity.
Regulatory Note: Failure to take appropriate action against this domain may result in liability under applicable laws and regulations, as well as potential penalties for non-compliance with your own policies.
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 kaynak · 09.08.2026 tarihinde eşitlendi
Tespit zaman çizelgesi
Kaydedilmiş gözlemler kronolojik sıradadır.
-
Kaydedilmiş gözlem
Kaydedilmiş gözlem: alive → dead
-
Cloudflare Radar
Cloudflare Radar: ilk kez https://radar.cloudflare.com/scan/88c03dee-fcf1-4613-a4f7-05f879ee5169 olarak gözlemlendi
-
Cloudflare Radar
Cloudflare Radar: ilk kez https://radar.cloudflare.com/scan/c0640d9f-0f22-4569-92a4-4005a7dc59ba olarak gözlemlendi
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
ICANN OVERSIGHT
Registration: stratorient.com
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For the registrable domain stratorient.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of ledger-live.stratorient.com · checked Mar 2, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin